SPF Check:
crl.eu

1. Specify domain name

Enter a domain to be checked for the SPF record
2. Specify IP address (optional)
Enter any IP address to check if it is authorized to send e-mails by the SPF record

What is the SPF lookup for?

With the SPF lookup you analyze the SPF record of a domain for errors, security risks and authorized IP addresses. Optionally, you can specify an IP address to check if it is authorized to send e-mail on behalf of the domain. The SPF lookup analyzes registered TXT records in real time. If you want to specify an SPF record manually, use the SPF Analyzer.

Loading...

SPF check passed

Your SPF record check result
  •   SPF record found
  •   Syntax check: 0 errors
  •   Email Anti-Spoofing: Good
Summary of the SPF check

Does a valid SPF record exist?
An SPF record was found for the domain crl.eu.
The SPF record for crl.eu is valid.
The syntax check of the SPF record shows no obvious errors.

Which IP-s are legitimate to send emails?
The SPF record contains a reference to external rules, which means that the validity of the SPF record depends on at least one other domain. A detailed list of the rules used externally can be found in the analysis result. In total, 54 IP address(es) were authorized by the SPF record to send emails.

The SPF record analysis was performed on 02.01.2026 at 16:16:04 clock.

Lookup for the domain:
crl.eu
IP address to be checked:
no IP address specified
Find out now: The BSI's Email Security Year 2025
This way, you'll be well prepared and can now strengthen your email security in a targeted manner.
Find out now: The BSI's Email Security Year 2025

Evaluation for the domain crl.eu 

Nameserverset:
ns4.p201.dns.oraclecloud.net
ns1.p201.dns.oraclecloud.net
ns2.p201.dns.oraclecloud.net
ns3.p201.dns.oraclecloud.net
Determined SPF record:
Legitimated IP addresses:
IP Provider / ASN DNSBL-Check
170.10.152.242 MIMECAST blacklist 
170.10.150.242 MIMECAST blacklist 
170.10.152.242 MIMECAST blacklist 
170.10.150.242 MIMECAST blacklist 
40.92.0.0/15
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
40.107.0.0/16
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
52.100.0.0/15
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
52.102.0.0/16
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
52.103.0.0/17
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
104.47.0.0/17
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f400::/48
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f403::/49
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f403:8000::/51
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f403:c000::/51
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
2a01:111:f403:f000::/52
MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
20.92.116.22 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
40.86.225.121 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
13.74.137.176 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
40.113.3.253 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
20.49.202.3 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
52.240.209.173 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
13.93.42.39 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
104.42.172.251 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
20.79.220.33 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
20.42.205.31 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
52.138.216.130 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
20.98.2.159 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
20.93.157.195 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
40.86.217.129 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
23.100.56.64 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
20.58.22.103 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
23.100.43.194 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
20.79.222.204 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
13.77.59.28 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
40.114.221.220 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
20.97.70.227 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
40.69.19.60 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
52.170.22.60 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
13.94.95.171 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
51.11.109.172 MICROSOFT-CORP-MSN-AS-BLOCK blacklist 
170.10.151.0/24
MIMECAST blacklist 
170.10.153.0/24
MIMECAST blacklist 
170.10.150.240/29
MIMECAST blacklist 
170.10.152.240/29
MIMECAST blacklist 
170.10.156.0/24
MIMECAST blacklist 
170.10.157.0/24
MIMECAST blacklist 
208.116.191.243 GTT Communications Inc. blacklist 
208.116.191.242 GTT Communications Inc. blacklist 
208.116.192.178 GTT Communications Inc. blacklist 
83.138.64.71 hostNET Medien GmbH blacklist 
83.138.69.121 hostNET Medien GmbH blacklist 
157.90.35.67 Hetzner Online GmbH blacklist 
2a01:4f8:251:5944::2 Hetzner Online GmbH blacklist 
12.9.145.68 ATT-INTERNET4 blacklist 
SPF-Syntax Check:
Analysis result of the SPF record for the domain: crl.eu

SPF record available?

We found an SPF record for the domain.

v=spf1

Additionally authorized A-records?

In addition to the A-records stored in the DNS, we were able to find further records authorized in the SPF-record

208.116.191.243
12.9.145.68

Are the registered mail servers allowed to send e-mails?

The mechanism 'mx' was set in the SPF entry. The following hosts are allowed to send

usb-smtp-inbound-2.mimecast.com
usb-smtp-inbound-2.mimecast.com
usb-smtp-inbound-1.mimecast.com
usb-smtp-inbound-1.mimecast.com

Additionally authorized IPv4 addresses

Explicit IPv4 addresses in the SPF record have been authorized to send

208.116.191.242
208.116.192.178
83.138.64.71
83.138.69.121
157.90.35.67

Additionally authorized IPv6 addresses

Explicit IPv6 addresses in the SPF record have been authorized to send

2a01:4f8:251:5944::2

Additional external SPF records

We could find other records authorized in the SPF record

include:spf.protection.outlook.com
v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all
ipv4:
40.92.0.0/15
ipv4:
40.107.0.0/16
ipv4:
52.100.0.0/15
ipv4:
52.102.0.0/16
ipv4:
52.103.0.0/17
ipv4:
104.47.0.0/17
ipv6:
2a01:111:f400::/48
ipv6:
2a01:111:f403::/49
ipv6:
2a01:111:f403:8000::/51
ipv6:
2a01:111:f403:c000::/51
ipv6:
2a01:111:f403:f000::/52
include:spf.emailsignatures365.com
v=spf1 ip4:20.92.116.22 ip4:40.86.225.121 ip4:13.74.137.176 ip4:40.113.3.253 ip4:20.49.202.3 ip4:52.240.209.173 ip4:13.93.42.39 ip4:104.42.172.251 ip4:20.79.220.33 ip4:20.42.205.31 ip4:52.138.216.130 ip4:20.98.2.159 ip4:20.93.157.195 ip4:40.86.217.129 ip4:23.100.56.64 ip4:20.58.22.103 ip4:23.100.43.194 ip4:20.79.222.204 ip4:13.77.59.28 ip4:40.114.221.220 ip4:20.97.70.227 ip4:40.69.19.60 ip4:52.170.22.60 ip4:13.94.95.171 ip4:51.11.109.172 -all
ipv4:
20.92.116.22
ipv4:
40.86.225.121
ipv4:
13.74.137.176
ipv4:
40.113.3.253
ipv4:
20.49.202.3
ipv4:
52.240.209.173
ipv4:
13.93.42.39
ipv4:
104.42.172.251
ipv4:
20.79.220.33
ipv4:
20.42.205.31
ipv4:
52.138.216.130
ipv4:
20.98.2.159
ipv4:
20.93.157.195
ipv4:
40.86.217.129
ipv4:
23.100.56.64
ipv4:
20.58.22.103
ipv4:
23.100.43.194
ipv4:
20.79.222.204
ipv4:
13.77.59.28
ipv4:
40.114.221.220
ipv4:
20.97.70.227
ipv4:
40.69.19.60
ipv4:
52.170.22.60
ipv4:
13.94.95.171
ipv4:
51.11.109.172
include:usb._netblocks.mimecast.com
v=spf1 ip4:170.10.151.0/24 ip4:170.10.153.0/24 ip4:170.10.150.240/29 ip4:170.10.152.240/29 ip4:170.10.156.0/24 ip4:170.10.157.0/24 ~all
ipv4:
170.10.151.0/24
ipv4:
170.10.153.0/24
ipv4:
170.10.150.240/29
ipv4:
170.10.152.240/29
ipv4:
170.10.156.0/24
ipv4:
170.10.157.0/24

Authorize IP addresses with markers

When SPF is evaluated, macros can specifically authorize Ip addresses based on the request or connection of the user or client (RFC7208 )

%{i}.spf.hc3367-37.iphmx.com
%{i}.spf.hc4015-20.iphmx.com

E-Mail handling

How should the checkHost() function of the e-mail server handle the e-mail? (syntax )

-all
Fail (non-compliant e-mails are rejected)

Unknown mechanisms

Unknown mechanisms were found in the SPF record


Will be forwarded to another SPF record?

There is no reference to any other SPF record

Are the server addresses allowed to send e-mails?

In the SPF entry the mechanism 'a' has not been set.

Additionally authorized MX records

We could not find any other records authorized in the SPF record besides the MX records stored in the DNS

How is the sender informed?

The exp mechanism acts as a return to the sender if the IP address was not authorized to send and notify them. None was found.

PTR (obsolete mechanism)

The ptr mechanism is deprecated, slow and insecure and should not be used

PTR:

The ptr mechanism is deprecated, slow and insecure and should not be used

Receiver address

analysis.ra-missing

Amount of reports

analysis.rp-missing

Report selection

analysis.rr-missing

Recently performed SPF lookups

Server IP Address

We have determined the following IP address for the domain:

No domain specified

Reverse address

We have determined the following name for the server IP address:

45.87.136.50

Free whitepaper

How secure is your domain?

  • Practical with many examples
  • the basics of domain risk management summarized in 20 pages
  • Checklist with 53 questions on 14 risk areas

Get a first impression of the risk potential in your company

⮩ Download "Domain Risk Management" for free
All offers are aimed at traders, not end consumers and do not include VAT.
© 2026 nicmanager.com.   All rights reserved.
nicmanager